<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pivot Boolean Lables in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Pivot-Boolean-Lables/m-p/95492#M2192</link>
    <description>&lt;P&gt;And how are you extracting the boolean attribute?  I think it has to have a value of either the string "true" or the string "false".  In my case I'm using an Eval and the expression looks like this:&lt;/P&gt;

&lt;P&gt;if(sourcetype == "foo", "true", "false")&lt;/P&gt;</description>
    <pubDate>Tue, 15 Oct 2013 14:46:08 GMT</pubDate>
    <dc:creator>Simon_Fishel</dc:creator>
    <dc:date>2013-10-15T14:46:08Z</dc:date>
    <item>
      <title>Pivot Boolean Lables</title>
      <link>https://community.splunk.com/t5/Reporting/Pivot-Boolean-Lables/m-p/95488#M2188</link>
      <description>&lt;P&gt;I'm working with splunk6, data models and pivot tables.  When I use the GUI function to relabel "True" and "False" to something more meaningful it doesn't actually display the labels.  &lt;/P&gt;

&lt;P&gt;Has anyone gotten the labels to actually show up in a pivot?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2013 23:53:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Pivot-Boolean-Lables/m-p/95488#M2188</guid>
      <dc:creator>ltawfall</dc:creator>
      <dc:date>2013-10-11T23:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: Pivot Boolean Lables</title>
      <link>https://community.splunk.com/t5/Reporting/Pivot-Boolean-Lables/m-p/95489#M2189</link>
      <description>&lt;P&gt;They work for me.  Can you describe how you set up the field in your data model?  And exactly what you're trying to do in pivot?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2013 23:55:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Pivot-Boolean-Lables/m-p/95489#M2189</guid>
      <dc:creator>Simon_Fishel</dc:creator>
      <dc:date>2013-10-14T23:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: Pivot Boolean Lables</title>
      <link>https://community.splunk.com/t5/Reporting/Pivot-Boolean-Lables/m-p/95490#M2190</link>
      <description>&lt;P&gt;Eh.. nothing fancy.&lt;/P&gt;

&lt;P&gt;I have a boolean field called "is_anonymous" to determine if the user is authenticated to the proxy or anonymously browsing.&lt;/P&gt;

&lt;P&gt;in the table, I split the column "is_anonymous" and relabeled "true == anonymous" and "false == authenticated" but the table still shows true/false as the table column headers, rather than using the labels.&lt;/P&gt;

&lt;P&gt;-l&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2013 23:59:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Pivot-Boolean-Lables/m-p/95490#M2190</guid>
      <dc:creator>ltawfall</dc:creator>
      <dc:date>2013-10-14T23:59:46Z</dc:date>
    </item>
    <item>
      <title>Re: Pivot Boolean Lables</title>
      <link>https://community.splunk.com/t5/Reporting/Pivot-Boolean-Lables/m-p/95491#M2191</link>
      <description>&lt;P&gt;Eh.. nothing fancy.&lt;/P&gt;

&lt;P&gt;I have a boolean field called "is_anonymous" to determine if the user is authenticated to the proxy or anonymously browsing.&lt;/P&gt;

&lt;P&gt;in the table, I split the column "is_anonymous" and relabeled "true == anonymous" and "false == authenticated" but the table still shows true/false as the table column headers, rather than using the labels.&lt;/P&gt;

&lt;P&gt;-l&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2013 23:59:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Pivot-Boolean-Lables/m-p/95491#M2191</guid>
      <dc:creator>ltawfall</dc:creator>
      <dc:date>2013-10-14T23:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: Pivot Boolean Lables</title>
      <link>https://community.splunk.com/t5/Reporting/Pivot-Boolean-Lables/m-p/95492#M2192</link>
      <description>&lt;P&gt;And how are you extracting the boolean attribute?  I think it has to have a value of either the string "true" or the string "false".  In my case I'm using an Eval and the expression looks like this:&lt;/P&gt;

&lt;P&gt;if(sourcetype == "foo", "true", "false")&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2013 14:46:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Pivot-Boolean-Lables/m-p/95492#M2192</guid>
      <dc:creator>Simon_Fishel</dc:creator>
      <dc:date>2013-10-15T14:46:08Z</dc:date>
    </item>
  </channel>
</rss>

